Logstash service will not stay on

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
cgutierr
Posts: 59
Joined: Tue Mar 08, 2016 1:09 pm

Re: Logstash service will not stay on

Post by cgutierr »

So, I copied what was is the file 99-nagioslogserver.conf file and appended it to the rsyslog.conf file and then restarted rsyslog.

I am using the defauly logstash configs 000_inputs.conf, 500_filters.conf, and 999_outputs.conf. I have setenforce set to 0 and iptables off.
User avatar
hsmith
Agent Smith
Posts: 3539
Joined: Thu Jul 30, 2015 11:09 am
Location: 127.0.0.1
Contact:

Re: Logstash service will not stay on

Post by hsmith »

Is it possible the logs are showing up in the 'future' ?

On your dashboard, in the upper right can you change the 'A month ago to a few seconds ago' to some crazy time range in the future using the custom button? Sometimes there's some weirdness about timestamps.
Former Nagios Employee.
me.
cgutierr
Posts: 59
Joined: Tue Mar 08, 2016 1:09 pm

Re: Logstash service will not stay on

Post by cgutierr »

Yeah, that worked! Sweet! How do we fix the issue with the timestamps?
User avatar
hsmith
Agent Smith
Posts: 3539
Joined: Thu Jul 30, 2015 11:09 am
Location: 127.0.0.1
Contact:

Re: Logstash service will not stay on

Post by hsmith »

Can I see a screenshot of one of the logs with any sensitive information obfuscated?
Former Nagios Employee.
me.
cgutierr
Posts: 59
Joined: Tue Mar 08, 2016 1:09 pm

Re: Logstash service will not stay on

Post by cgutierr »

Unfortunately, I cannot. Is there anything in particular you are looking for?
User avatar
hsmith
Agent Smith
Posts: 3539
Joined: Thu Jul 30, 2015 11:09 am
Location: 127.0.0.1
Contact:

Re: Logstash service will not stay on

Post by hsmith »

I wanted to see what the timestamp differences look like. Specifically the message field, and any field with the word timestamp in it/any field that relates to time.

Here are some links for reference to what's going on: https://discuss.elastic.co/t/timestamp- ... ture/29421
https://support.nagios.com/forum/viewto ... 37&t=34084
Former Nagios Employee.
me.
cgutierr
Posts: 59
Joined: Tue Mar 08, 2016 1:09 pm

Re: Logstash service will not stay on

Post by cgutierr »

Basically, the timestamp value on the left column is correct but when you expand the message, the timestamp value inside the message is about 7 hours off.
jolson
Attack Rabbit
Posts: 2560
Joined: Thu Feb 12, 2015 12:40 pm

Re: Logstash service will not stay on

Post by jolson »

Please read through the following document to learn about how dates work with relation to Nagios Log Server: https://www.elastic.co/guide/en/logstas ... -date.html

I am betting that either:

1. Your system time is off

2. You have a syslog input or a date filter that is re-doing the time of your inbound logs.

In either case, reading the above article will be useful. Let me know if you have any questions about it!
Twits Blog
Show me a man who lives alone and has a perpetually clean kitchen, and 8 times out of 9 I'll show you a man with detestable spiritual qualities.
cgutierr
Posts: 59
Joined: Tue Mar 08, 2016 1:09 pm

Re: Logstash service will not stay on

Post by cgutierr »

Can you please close thread.
Locked